GDPR Compliance
Your rights and our commitment to data protection
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, across the European Union (EU) and European Economic Area (EEA). CRMPro, operated by Digital Works Technologies Ltd, is fully committed to GDPR compliance and protecting the privacy rights of all individuals whose personal data we process.
This page outlines our GDPR compliance measures, your rights under GDPR, and how we ensure the lawful, fair, and transparent processing of personal data through our CRMPro platform.
Last Updated: November 4, 2025
CRMPro adheres to all six principles of GDPR when processing personal data:
Lawfulness, Fairness, and Transparency
We process personal data lawfully, fairly, and in a transparent manner. We clearly communicate how and why we collect your data.
Purpose Limitation
We collect personal data for specified, explicit, and legitimate purposes only. We do not use your data in ways incompatible with those purposes.
Data Minimization
We only collect personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
Accuracy
We ensure personal data is accurate and kept up to date. We take reasonable steps to erase or rectify inaccurate data without delay.
Storage Limitation
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law.
Integrity and Confidentiality
We implement appropriate technical and organizational measures to ensure data security, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage.
As a data subject under GDPR, you have the following rights:
Right to Be Informed
You have the right to be informed about the collection and use of your personal data. We provide this information through our Privacy Policy and this GDPR page.
Right of Access
You have the right to request access to your personal data. We will provide you with a copy of the personal data we hold about you within one month of your request.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. You can update most of your information directly through your account settings.
Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data in certain circumstances, such as when:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required to comply with a legal obligation
Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another data controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests, direct marketing, or processing for scientific/historical research purposes.
Rights Related to Automated Decision Making and Profiling
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we use AI for candidate matching or lead scoring, human oversight is always involved in final decisions.
How to Exercise Your Rights
To exercise any of these rights, please contact our Data Protection Officer at:
dpo@digitalworkstechnologies.co.uk
We will respond to your request within 30 days. In complex cases, we may extend this by an additional 60 days.
Under GDPR, we must have a legal basis to process your personal data. We process personal data on the following legal bases:
Consent
We process certain personal data based on your explicit consent, such as:
- Marketing communications and promotional emails
- Optional cookies and analytics
- Job application submissions where you opt-in for future opportunities
You have the right to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing based on consent before withdrawal.
Contract Performance
We process personal data when necessary to fulfill our contractual obligations to you, including:
- Providing access to the CRMPro platform
- Processing CRM and employee management activities
- Facilitating communication between parties
- Billing and payment processing
Legal Obligation
We process personal data to comply with legal obligations, such as:
- Employment law requirements
- Tax and accounting regulations
- Data protection and privacy laws
- Court orders and legal proceedings
Legitimate Interests
We process certain personal data based on our legitimate interests, such as:
- Improving and optimizing our services
- Fraud prevention and security
- Network and information security
- Internal administration and business operations
We balance our legitimate interests against your rights and freedoms. You have the right to object to processing based on legitimate interests.
CRMPro may transfer personal data outside the European Economic Area (EEA) to countries that may not provide the same level of data protection as your home country.
Safeguards for International Transfers
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
Standard Contractual Clauses (SCCs)
We use the European Commission's Standard Contractual Clauses (also known as Model Clauses) with our service providers and partners outside the EEA.
Adequacy Decisions
Where possible, we transfer data to countries that have been deemed by the European Commission to provide an adequate level of data protection.
Binding Corporate Rules
For transfers within our corporate group, we implement binding corporate rules that ensure GDPR-level protection across all jurisdictions.
For more information about our international data transfer practices, please contact our Data Protection Officer.
We implement state-of-the-art technical and organizational measures to ensure a level of security appropriate to the risk of processing personal data:
Technical Measures
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access control (RBAC) ensures users only access necessary data
- Authentication: Multi-factor authentication (MFA) available for enhanced security
- Network Security: Firewalls, intrusion detection/prevention systems, and DDoS protection
- Secure Development: Regular security testing, code reviews, and vulnerability assessments
- Data Backup: Regular encrypted backups with disaster recovery procedures
Organizational Measures
- Staff Training: Regular GDPR and data protection training for all employees
- Access Management: Strict policies on who can access personal data and when
- Incident Response: Documented procedures for detecting, reporting, and investigating breaches
- Vendor Management: Due diligence and data protection agreements with all processors
- Privacy by Design: Data protection integrated into all new systems and processes
- Regular Audits: Internal and external audits of our data protection practices
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (within 72 hours of becoming aware). We will also notify the relevant supervisory authority as required by law.
Data Controller vs. Data Processor
When You Are the Data Controller
If you use CRMPro to process personal data about your contacts, employees, or customers, you are the data controller. This means you:
- Determine the purposes and means of processing personal data
- Are responsible for GDPR compliance regarding that data
- Must have a lawful basis for processing
- Must provide privacy notices to data subjects
- Must respond to data subject rights requests
- Are responsible for obtaining necessary consents
When CRMPro Is the Data Processor
CRMPro acts as a data processor on your behalf when you use our platform. As your processor, we:
- Process personal data only on your documented instructions
- Implement appropriate technical and organizational measures
- Ensure our staff are bound by confidentiality
- Assist you in responding to data subject rights requests
- Assist you with data breach notifications
- Delete or return data upon termination of services
- Make available information necessary to demonstrate compliance
Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing our GDPR compliance program. You can contact our DPO with any questions or concerns:
Data Protection Officer
Email: dpo@digitalworkstechnologies.co.uk
Our DPO is available to assist with GDPR-related inquiries, data subject rights requests, and any data protection concerns.
Special categories of personal data (also known as "sensitive personal data") receive heightened protection under GDPR. These include data revealing:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data
- Health data
- Sex life or sexual orientation
Our Approach to Special Categories
CRMPro minimizes processing of special category data. Where such processing is necessary (e.g., health data for employee benefits), we:
- Obtain explicit consent where required
- Process only when necessary for employment law compliance
- Implement enhanced security measures
- Conduct Data Protection Impact Assessments (DPIAs)
- Provide clear information about why such data is needed
- Limit access to authorized personnel only
Important: As a data controller using CRMPro, you are responsible for ensuring you have a lawful basis to collect and process special category data. We recommend consulting with legal counsel if you plan to process such data.
We conduct Data Protection Impact Assessments (DPIAs) for processing operations that are likely to result in a high risk to individuals' rights and freedoms, including:
- Large-scale processing of special category data
- Systematic monitoring of public areas
- Automated decision-making with legal or significant effects
- Processing of vulnerable individuals' data at scale
- New technologies or processing methods
Our DPIAs systematically analyze processing operations and assess:
- The nature, scope, context, and purposes of processing
- The necessity and proportionality of processing
- Risks to individuals' rights and freedoms
- Measures to address and mitigate those risks
As a data controller using CRMPro, you may need to conduct your own DPIAs depending on how you use our platform. We're happy to provide information about our processing activities to support your DPIA process.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law:
Retention Periods
Account Data
Duration of active subscription + 90 days after cancellation
Contact & CRM Data
Duration of active subscription + 90 days after cancellation, or upon deletion request
Financial Records
7 years (for tax and legal compliance)
Audit Logs
3 years (for security and compliance)
Marketing Communications
Until unsubscribe or deletion request
Secure Deletion
When personal data reaches the end of its retention period or you request deletion, we ensure secure deletion by:
- Permanently erasing data from all active systems
- Removing data from backups within 90 days
- Ensuring data cannot be reconstructed or recovered
- Maintaining records of deletion for audit purposes
Under GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement.
Contact Your Local Supervisory Authority
If you believe we have not handled your personal data in accordance with GDPR, you can file a complaint with your local data protection authority. You can find your local authority through the European Data Protection Board website.
Before Filing a Complaint
We encourage you to contact us first at dpo@digitalworkstechnologies.co.uk so we can try to resolve your concerns directly.
However, this does not affect your right to lodge a complaint with a supervisory authority at any time.
UK Users
For users in the United Kingdom, the relevant supervisory authority is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
CRMPro is committed to maintaining the highest standards of data protection and GDPR compliance:
Regular Audits
We conduct regular internal audits and third-party assessments of our GDPR compliance measures.
Staff Training
All employees receive mandatory GDPR training upon joining and annual refresher courses.
Privacy by Design
We integrate data protection principles into all new products, features, and business processes from the outset.
Continuous Improvement
We regularly review and update our policies, procedures, and technical measures to ensure ongoing compliance.
We maintain detailed records of our processing activities as required by Article 30 of GDPR and can provide documentation upon request.
Related Documents